Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Snort blacklist subnet not working

    Scheduled Pinned Locked Moved IDS/IPS
    2 Posts 2 Posters 244 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J
      jonathan.young
      last edited by

      Hi,

      I want to block a whole subnet of ip addresses inside snort (e.g. 81.22.45.0/24 ) as I can see they are generating a lot of alerts. I have added this subnet to an IP List file and then applied that to my WAN IP Rep Blacklist files list.

      The problem is that ip addresses in this subnet are still generating alerts. I thought that the IP Rep blacklist would be processed before examing my rulesets. Is this right?

      How do I block a subnet before it gets to being processed by my snort rules?

      Thanks for the help!

      1 Reply Last reply Reply Quote 0
      • bmeeksB
        bmeeks
        last edited by bmeeks

        It is processed first and then those IPs don't hit the other rules, but they will still generate a "blacklist" alert. Are you getting alerts beside the "blacklist" alert?

        1 Reply Last reply Reply Quote 0
        • First post
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.